瀏覽代碼

Btrfs: fix file clone ioctl for bookend extents

The file clone ioctl was incorrectly taking the offset into the
extent on disk into account when calculating the length of the
cloned extent.

The length never changes based on the offset into the physical extent.

Test case:

fallocate -l 1g image
mke2fs image
bcp image image2
e2fsck -f image2

(errors on image2)

The math bug ends up wrapping the length of the extent, and things
go wrong from there.

Signed-off-by: Chris Mason <chris.mason@oracle.com>
Chris Mason 15 年之前
父節點
當前提交
ac6889cbb2
共有 1 個文件被更改,包括 4 次插入2 次删除
  1. 4 2
      fs/btrfs/ioctl.c

+ 4 - 2
fs/btrfs/ioctl.c

@@ -1123,8 +1123,10 @@ static noinline long btrfs_ioctl_clone(struct file *file, unsigned long srcfd,
 					datao += off - key.offset;
 					datao += off - key.offset;
 					datal -= off - key.offset;
 					datal -= off - key.offset;
 				}
 				}
-				if (key.offset + datao + datal > off + len)
-					datal = off + len - key.offset - datao;
+
+				if (key.offset + datal > off + len)
+					datal = off + len - key.offset;
+
 				/* disko == 0 means it's a hole */
 				/* disko == 0 means it's a hole */
 				if (!disko)
 				if (!disko)
 					datao = 0;
 					datao = 0;